CVE-2018-7602: Drupal Core Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 99.2% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Drupal Drupal: from 7.0, before 7.59 (fixed in 7.59); from 8.4.0, before 8.4.8 (fixed in 8.4.8); from 8.5.0, before 8.5.3 (fixed in 8.5.3)
Published 2018-07-19. Last modified 2026-10-02.